Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12496— Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server

CVSS 8.7 · High EPSS 0.36% · P29

Affected Version Matrix 8

VendorProductVersion RangeStatus
LoytecL-DALI≤ 8.4.16affected
LoytecL-GATE≤ 8.4.16affected
LoytecL-INX≤ 8.4.16affected
LoytecL-IOB≤ 8.4.16affected
LoytecL-PAD≤ 8.4.16affected
LoytecL-ROC≤ 8.4.16affected
LoytecL-VIS≤ 8.4.16affected
LoytecLIP-ME20xC≤ 8.4.16affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-12496

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
Source: CVE Program / CVE List V5
Vulnerability Description
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5
Vulnerability Title
LOYTEC LIP-ME20xC 输出处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LOYTEC LIP-ME20xC是LOYTEC公司的一款工业路由器。 Loytec LIP-ME201C、L-INX、L-GATE、L-ROC、L-IOB、L-DALI、L-VIS和L-PAD 8.4.16及之前版本存在安全漏洞,该漏洞源于OPC XML-DA服务器统计页面存在存储型跨站脚本,可能导致未经身份验证的远程攻击者在管理员浏览器中执行任意JavaScript,导致会话劫持、凭据窃取、设备重新配置,攻击者通过在`POST /da`请求中构造`User-Agent`标头触发。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LoytecLIP-ME20xC 0 ~ 8.4.16 -
LoytecL-INX 0 ~ 8.4.16 -
LoytecL-GATE 0 ~ 8.4.16 -
LoytecL-ROC 0 ~ 8.4.16 -
LoytecL-IOB 0 ~ 8.4.16 -
LoytecL-DALI 0 ~ 8.4.16 -
LoytecL-VIS 0 ~ 8.4.16 -
LoytecL-PAD 0 ~ 8.4.16 -

II. Public POCs for CVE-2026-12496

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12496

登录查看更多情报信息。

Vendor Advisories for CVE-2026-12496 (1)

Same Patch Batch · Loytec · 2026-07-24 · 9 CVEs total

CVE-2026-125039.2 CRITICALLoytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter
CVE-2026-557308.7 HIGHLoytec LWEB802: Reflected Cross-Site Scripting in LWEB802
CVE-2026-557328.7 HIGHLoytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)
CVE-2026-125028.4 HIGHLoytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo
CVE-2026-125048.4 HIGHLoytec LINX firmware: Improper Authentication in PAM configuration
CVE-2026-557297.7 HIGHLoytec LWEB802: Exposure of Sensitive Information in browser localStorage
CVE-2026-557316.6 MEDIUMLoytec LINX firmware: Unchecked input for loop condition in the SNMP agent
CVE-2026-557283.8 LOWLoytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict

IV. Related Vulnerabilities

V. Comments for CVE-2026-12496

No comments yet


Leave a comment